A DoS policy applies to inbound, outbound, and bidirectional traffic. Inbound traffic is that traffic received on the port marked outside, that is, originating from outside the network, in inline mode. Typically inbound traffic is destined to the protected network, such as an enterprise intranet. Outbound traffic is that traffic sent from a system in your intranet, and is on the port marked inside, that is, originating from inside the network, in inline mode.
Bidirectional attacks reflect changes in the distribution of ECHO requests and replies in both inbound and outbound. For example, if the Sensor normally sees 50 percent inbound replies and 50 percent outbound replies, but then the distribution changes to 70 percent / 30 percent, the change might raise an alert.
Note
There are also learning mode attacks that do not have a directional association, specifically ICMP ECHO anomaly and TCP control anomaly. Note that Sensors can only raise an alert in case of ICMP echo anomaly and TCP control anomaly attacks but cannot block them, even when in inline mode.
The Sensor applies the outbound or inbound DoS policy depending on the traffic direction, which is determined through the Sensor cabling and port configuration. The drop attack packets response action must be enabled by traffic type (protocol type) within the DoS policy.
When the Sensor detects an attack traffic condition, the block action will persist until the attack condition ends and will repeat whenever the attack condition is present.